# Probéme avec logstash

**URL:** <https://discuss.elastic.co/t/probeme-avec-logstash/60919>\
**Category:** Discussions en français\
**Created:** [September 19, 2016, 5:03pm UTC](https://discuss.elastic.co/t/probeme-avec-logstash/60919 "2016-09-19T17:03:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aboumejd\_younes](https://avatars.discourse-cdn.com/v4/letter/a/9f8e36/32.png) [@aboumejd\_younes](https://discuss.elastic.co/u/aboumejd_younes)\
**Post date:** [September 19, 2016, 5:03pm UTC](https://discuss.elastic.co/t/probeme-avec-logstash/60919/1 "2016-09-19T17:03:45Z")

</div>

je veux consulter des logs avec ELK (ElasticSearch – Logstash – Kibana)

j'ai des problème avec logstash j'ai crée un fichier config (logstash.conf)

input {  
file {  
path =\> 'C:\Users\younes\Desktop\projet\Apache24\logs\logtest.log'  
}  
}

filter {  
grok {  
match =\> {  
"message" =\> "%{COMBINEDAPACHELOG} %{IPORHOST:serverip} %{NUMBER:serverport} %{NUMBER:elapsed\_millis} %{NOTSPACE:sessionid} %{QS:proxiedip} %{QS:loginame}"  
}  
overwrite =\> ["message"]  
remove\_field =\> ["ident", "auth"]  
}  
useragent {  
source =\> "agent"  
target =\> "ua"  
remove\_field =\> ["agent"]  
}  
mutate {  
gsub =\> [  
"request", "?.+", "",  
"proxiedip", "(^"|"$)", "",  
"loginame", "(^"|"$)" , "",  
"referrer", "(^"|"$)" , ""  
]  
}  
if [proxiedip] != "-" {  
mutate {  
replace =\> {  
"clientip" =\> "%{proxiedip}"  
}  
}  
}  
if ![bytes] {  
mutate {  
add\_field =\> {  
"bytes" =\> "0"  
}  
}  
}  
mutate {  
remove\_field =\> ["proxiedip"]  
}  
mutate {  
convert =\> {  
"bytes" =\> "integer"  
"elapsed\_millis" =\> "integer"  
"serverport" =\> "integer"  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
stdout {  
codec =\> plain {  
charset =\> "ISO-8859-1"  
}

```
}
elasticsearch {
	
	template => "apache_template.json"
	template_name => "apache_log"
	template_overwrite => true
}

```

}  
et un autre JSON  
{

"template": "apache\_log",  
"settings": {  
"index.refresh\_interval": "5s"  
},  
"mappings": {  
"_default_": {  
"dynamic\_templates": [  
{  
"message\_field": {  
"mapping": {  
"index": "analyzed",  
"omit\_norms": true,  
"type": "string"  
},  
"match\_mapping\_type": "string",  
"match": "message"  
}  
},  
{  
"string\_fields": {  
"mapping": {  
"index": "analyzed",  
"omit\_norms": true,  
"type": "string",  
"fields": {  
"raw": {  
"index": "not\_analyzed",  
"ignore\_above": 256,  
"type": "string"  
}  
}  
},  
"match\_mapping\_type": "string",  
"match": "\*"  
}  
}  
],  
"properties": {  
"geoip": {  
"dynamic": true,  
"properties": {  
"location": {  
"type": "geo\_point"  
}  
},  
"type": "object"  
},  
"@version": {  
"index": "not\_analyzed",  
"type": "string"  
}  
},  
"_all": {  
"enabled": true  
}  
}  
}  
}  
voila mon fichier log (c'est just un exemple)  
45.217.184.114 - - [05/Sep/2016:21:58:26 +0000] "GET /rs-web/rechercherContratAutoPagineted.do?sEcho=1&iColumns=13&sColumns=%2C%2C%2C%2C%2C%2C%2C%2C%2C%2C%2C%2C&iDisplayStart=0&iDisplayLength=5&mDataProp\_0=0&sSearch\_0=&bRegex\_0=false&bSearchable\_0=true&mDataProp\_1=1&sSearch\_1=&bRegex\_1=false&bSearchable\_1=true&mDataProp\_2=2&sSearch\_2=&bRegex\_2=false&bSearchable\_2=true&mDataProp\_3=3&sSearch\_3=&bRegex\_3=false&bSearchable\_3=true&mDataProp\_4=4&sSearch\_4=&bRegex\_4=false&bSearchable\_4=true&mDataProp\_5=5&sSearch\_5=&bRegex\_5=false&bSearchable\_5=true&mDataProp\_6=6&sSearch\_6=&bRegex\_6=false&bSearchable\_6=true&mDataProp\_7=7&sSearch\_7=&bRegex\_7=false&bSearchable\_7=true&mDataProp\_8=8&sSearch\_8=&bRegex\_8=false&bSearchable\_8=true&mDataProp\_9=9&sSearch\_9=&bRegex\_9=false&bSearchable\_9=true&mDataProp\_10=10&sSearch\_10=&bRegex\_10=false&bSearchable\_10=true&mDataProp\_11=11&sSearch\_11=&bRegex\_11=false&bSearchable\_11=true&mDataProp\_12=12&sSearch\_12=&bRegex\_12=false&bSearchable\_12=true&sSearch=&bRegex=false&_=1473108677432 HTTP/1.1" 200 330 "[https://196.12.229.28:9448/rs-web/initRechercheContratAuto.do](https://196.12.229.28:9448/rs-web/initRechercheContratAuto.do)" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 10.10.11.168 9448 104 7706FC223C392F1E1F8DEB2AE74A0EE1.jvm1 "-" "-"

quand j’exécute la commande logstash -f logstash.conf  
elasticsearch me donne  
{  
"took": 4,  
"timed\_out": false,  
"\_shards": {  
"total": 1,  
"successful": 1,  
"failed": 0  
},  
"hits": {  
"total": 1,  
"max\_score": 1,  
"hits": [  
{  
"\_index": ".kibana",  
"\_type": "config",  
"\_id": "4.4.2",  
"\_score": 1,  
"\_source": {  
"buildNum": 9732  
}  
}  
]  
}  
}  
je comprend pas ! de l'aide svp

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 19, 2016, 5:47pm UTC](https://discuss.elastic.co/t/probeme-avec-logstash/60919/2 "2016-09-19T17:47:13Z")

</div>

Peux-tu formater ton POST STP pour le rendre lisible ? Utilise cet icône `</>`.

---

<div class="post-metadata">

**Author:** ![aboumejd\_younes](https://avatars.discourse-cdn.com/v4/letter/a/9f8e36/32.png) [@aboumejd\_younes](https://discuss.elastic.co/u/aboumejd_younes)\
**Post date:** [September 19, 2016, 6:42pm UTC](https://discuss.elastic.co/t/probeme-avec-logstash/60919/3 "2016-09-19T18:42:50Z")

</div>

(logstash.conf)

input {  
file {  
path =\> 'C:\Users\younes\Desktop\projet\Apache24\logs\logtest.log'  
}  
}

filter {  
grok {  
match =\> {  
"message" =\> "%{COMBINEDAPACHELOG} %{IPORHOST:serverip} %{NUMBER:serverport} %{NUMBER:elapsed\_millis} %{NOTSPACE:sessionid} %{QS:proxiedip} %{QS:loginame}"  
}  
overwrite =\> ["message"]  
remove\_field =\> ["ident", "auth"]  
}  
useragent {  
source =\> "agent"  
target =\> "ua"  
remove\_field =\> ["agent"]  
}  
mutate {  
gsub =\> [  
"request", "?.+", "",  
"proxiedip", "(^"|"$)", "",  
"loginame", "(^"|"$)" , "",  
"referrer", "(^"|"$)" , ""  
]  
}  
if [proxiedip] != "-" {  
mutate {  
replace =\> {  
"clientip" =\> "%{proxiedip}"  
}  
}  
}  
if ![bytes] {  
mutate {  
add\_field =\> {  
"bytes" =\> "0"  
}  
}  
}  
mutate {  
remove\_field =\> ["proxiedip"]  
}  
mutate {  
convert =\> {  
"bytes" =\> "integer"  
"elapsed\_millis" =\> "integer"  
"serverport" =\> "integer"  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
stdout {  
codec =\> plain {  
charset =\> "ISO-8859-1"  
}

```
}
elasticsearch {
	
	template => "apache_template.json"
	template_name => "apache_log"
	template_overwrite => true
}

```

}`

(apache\_template.json)

```
{

  "template": "apache_log",
  "settings": {
     "index.refresh_interval": "5s"
  },
  "mappings": {
     "_default_": {
        "dynamic_templates": [
           {
              "message_field": {
                 "mapping": {
                    "index": "analyzed",
                    "omit_norms": true,
                    "type": "string"
                 },
                 "match_mapping_type": "string",
                 "match": "message"
              }
           },
           {
              "string_fields": {
                 "mapping": {
                    "index": "analyzed",
                    "omit_norms": true,
                    "type": "string",
                    "fields": {
                       "raw": {
                          "index": "not_analyzed",
                          "ignore_above": 256,
                          "type": "string"
                       }
                    }
                 },
                 "match_mapping_type": "string",
                 "match": "*"
              }
           }
        ],
        "properties": {
           "geoip": {
              "dynamic": true,
              "properties": {
                 "location": {
                    "type": "geo_point"
                 }
              },
              "type": "object"
           },
           "@version": {
              "index": "not_analyzed",
              "type": "string"
           }
        },
        "_all": {
           "enabled": true
        }
     }
  }
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 19, 2016, 6:56pm UTC](https://discuss.elastic.co/t/probeme-avec-logstash/60919/4 "2016-09-19T18:56:33Z")

</div>

Pas la peine de soumettre une réponse. Tu peux éditer le texte d'origine.  
A noter que le formatage n'est toujours pas bon.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:45pm UTC](https://discuss.elastic.co/t/probeme-avec-logstash/60919/5 "2017-07-06T13:45:22Z")

</div>


